PT-2024-27774 · Itsourcecode · Itsourcecode Payroll Management System

·

CVE-2024-37831

·

Published

2024-06-14

·

Updated

2024-08-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Itsourcecode Payroll Management System version 1.0
Description The issue is related to SQL Injection in the payroll items.php file via the ID parameter. This allows for potential exploitation.
Recommendations For Itsourcecode Payroll Management System version 1.0, consider restricting access to the payroll items.php file or the ID parameter to minimize the risk of exploitation until a fix is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37831

Affected Products

Itsourcecode Payroll Management System